No system is perfect, but how can that be used as an excuse to avoid improvement? Keep defending an approach that clearly does not operate well does not solve the issue...
Also, can you explicitly respond to the points raised?
If they are a real security risk, why this process is unable to...